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DETAILED ACTION 

This action is in response to an amendment filed19 March 2007. Claims 1-48 are 
presented for further consideration. Claim 48 is currently amended. 



Response to Arguments 

Applicant's arguments, see Remarks, filed 19 March 2007, with respect to claims 
8-1 1,14-22, 28, 43-44 and 46-47 have been fully considered and are persuasive. The 
rejection of the aforementioned claims has been withdrawn. 

In considering Applicant's arguments the following factual remarks are noted: 

(I) Applicant contends that Diets fails to teach analyzing usage data record events. 

(II) Applicant contends that Rosenberg fails to teach or suggest updating only a 
portion of the statistical model associated with the identifier. 

(III) Applicant contends that there is no teaching or suggestion to combine Dietz and 
Rosenberg. 

In considering (I), Applicant contends that Dietz fails to teach analyzing usage data 
record events. Examiner respectfully disagrees. Examiner asserts that Dietz discloses 
that real-time data is collected from a stream of packets corresponding to a 
conversational flow, wherein information contained within the packet is further extracted 
in order to obtain more specific data regarding the usage of an end user (column 3, 
lines 23-43; column 5, lines 19-34). Examiner additionally asserts that according to 



I 
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Applicant's specification, a user data event record is disclosed to comprise real-time 
stream of usage data (page 9, lines 23-26). Therefore, it is evident that the packets of 
Dietz are collected in accordance with the claimed usage data records. Furthermorie, 
although Dietz discloses deriving network metrics from statistical measurements, this 
fails to suggest that usage data is not analyzed from the monitored packets, so as to 
build the statistical models as suggested by Applicant. Therefore, the Examiner 
maintains rejections as set forth below in the Office action. 

In considering (II), Applicant contends that Rosenberg fails to teach updating only a 
portion of the statistical model associated with the identifier. Examiner respectfully 
disagrees. Examiner asserts that Rosenberg expressly discloses that advantages of 
analyzing a subset of larger amount statistical data in order to more efficiently handle 
larger scale data analysis problems (paragraph [0067], lines 7-25). Specifically, 
Rosenberg discloses performing statistical analysis operations solely on a specific 
dataset within the larger dataset, in the particular example namely data restricted to the 
variables sex and male. Therefore, it logically follows that the updating of the statistical 
model as disclosed by Rosenberg would similarly update a subset of the gathered 
statistical data in the model, namely the newly provided input data, without requiring the 
model operation to be performed entirely over the larger dataset. Examiner also asserts 
that Rosenberg fails to explicitly disclose that the entire statistical model is 
reconstructed when the input is changed, as suggested by Applicant. Furthermore, 
Applicant fails to provide a specific citation in the Rosenberg reference to further 
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substantiate this assertion. Therefore, Examiner maintains rejections as set forth below 
in the Office action. 

In considering (III), Applicant contends that there is no suggestion to combine Dietz and 
Rosenberg. Examiner recognizes that obviousness can only be established by 
combining or modifying the teachings of the prior art to produce the claimed invention 
where there is some teaching, suggestion, or motivation to do so found either in the 
references themselves or in the knowledge generally available to one of ordinary skill in 
the art. See In re Fine, 837 F.2d 1071, 5 USPQ2d 1596 (Fed. Cir. 1988)and In re 
Jones, 958 F.2d 347, 21 USPQ2d 1941 (Fed. Cir. 1992). In this case, the modification 
to teachings of would have been obvious, because one of ordinary skill in the art would 
have been so motivated to present statistical summaries in a coherent and efficient 
manner for subset analysis to tackle large-scale problems (Rosenberg; paragraph 
[0067], lines 22-24; paragraph [0073], lines 8-12). Furthermore, Examiner asserts that 
both Dietz and Rosenberg are pertaining to statistical analysis of collected data, and 
therefore suggest the combination in accordance with that particular aspect of the 
network data analysis as taught by Dietz. Furthermore, the assertion that MATLAB is 
not capable of processing data in real-time does not render the combination inoperable. 
Therefore, 6 the Examiner asserts that motivation to modify Dietz in view of Rosenberg 
is evident. 
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Claim Rejections - 35 USC § 103 

The following is a quotation of 35 U.S.C. 103(a) which forms the basis for all 
obviousness rejections set forth in this Office action: 

(a) A patent may not be obtained though the invention is not identically disclosed or described as set 
forth in section 1 02 of this title, if the differences between the subject matter sought to be patented and 
the prior art are such that the subject matter as a whole would have been obvious at the time the 
invention was made to a person having ordinary skill in the art to which said subject matter pertains. 
Patentability shall not be negatived by the manner in which the invention was made. 

Claims 1 and 13 are rejected under 35 U.S.C. 103(a) as being unpatentable 
over Dietz et al (US Patent 6,839,751) in view of Rosenberg et al. (US Patent 
Application Publication 2003/0023951), hereinafter referred to as Dietz and 
Rosenberg. 

In reference to claim 1, Dietz discloses a method for re-using information from data 
transactions for maintaining statistics in network monitoring. Dietz discloses (abstract; 
column 4, lines 14-33): 

• A method for analyzing a stream of usage data (Figure 3; column 8, lines 45-56), 
comprising: 

• Generating a statistical model (i.e. statistical measures/network usage metrics; 
column 3, lines 14-33; column 17, lines 35-53) from a set of record events (i.e. 
flow-entry; column 10, line 55-column 11, line 5); 

• Receiving a most recent record event, (i.e. new packet of flow arrives at monitor; 
column 8, lines 45-62; Figure 3-item 302) and 

• Updating the statistical model using the most recent event by adding the most 
recent record to the statistical model (updating statistical measures stored in the 
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flow-entry; column 11, lines 50-58; column 12, lines 55-67), wherein an identifier 
is associated with each record event (i.e. unique flow signature; column 11, lines 
15-49), 

However, the reference fails to disclose updating only a portion of the statistical model 
associated with the identifier. Nonetheless, this would have been an obvious 
modification to the aforementioned method to one of ordinary skill in the art at the time 
of the invention, as further evidenced by Rosenberg. 

In an analogous art, Rosenberg discloses a method for data analysis and 
statistical modeling (abstract). Rosenberg further discloses updating only a portion of 
the statistical model associated with the identifier (i.e. updating statistical model for the 
new input data; paragraphs [0071]-[0073]; paragraph [0067]). This modification to the 
aforementioned method would have been obvious, because one of ordinary skill in the 
art would have been so motivated to present statistical summaries in a coherent and 

* 

efficient manner for subset analysis to tackle large-scale problems (Rosenberg; 
paragraph [0067], lines 22-24; paragraph [0073], lines 8-12). 

In reference to claim 13, Dietz discloses a method for re-using information from data 
transactions for maintaining statistics in network monitoring. Dietz discloses (abstract; 
column 4, lines 14-33): 

• A method for analyzing a stream of usage data (Figure 3; column 8, lines 45-56) 
over a rolling time interval, comprising: 

• Defining a statistical model (i.e. statistical measures/network usage metrics; 
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column 3, lines 14-33; column 17, lines 35-53) from a set of record events (i.e. 
flow-entry; column 10, line 55-column 11, line 5); 

• Defining the rolling time interval to include a plurality of update time intervals (i.e. 
time interval; column 33, line 15-column 34, line 30); 

• Receiving a record event from the stream of network usage data over the rolling 
time interval, (i.e. new packet of flow arrives at monitor; column 8, lines 45-62; 
Figure 3-item 302); 

• Storing the record event for each update interval in a history cache (i.e. cache 
memory containing flow database; column 17, lines 4-34); 

• Generating a statistical model (i.e. statistical measures/network usage metrics; 
column 3, lines 14-33; column 17, lines 35-53) over the rolling time interval using 
the statistical model and each record event stored in the history cache (i.e. flow- 
entry; column 10, line 55-column 11, line 5); 

• Updating the statistical model using the statistical model and a most recent event 
for a most recent update time, interval (updating statistical measures stored in the 
flow-entry; column 11, lines 50-58; column 12, lines 55-67). 

However, the reference fails to disclose updating only a portion of the statistical model 
associated with the most recent record. Nonetheless, this would have been an obvious 
modification to the aforementioned method to one of ordinary skill in the art at the time 
of the invention, as further evidenced by Rosenberg. 

In an analogous art, Rosenberg discloses a method for data analysis and 
statistical modeling (abstract). Rosenberg further discloses updating only a portion of 
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the statistical model associated with the most recent record (i.e. updating statistical 
model for the new input data; paragraphs [0071]-[0073]; paragraph [0067]). This 
modification to the aforementioned method would have been obvious, because one of 
ordinary skill in the art would have been so motivated to present statistical summaries in 
a coherent and efficient manner for subset analysis to tackle large-scale problems 
(Rosenberg; paragraph [0067], lines 22-24; paragraph [0073], lines 8-12). 

Claim 23, 25-26, 37, 45 and 48 are rejected under 35 U.S.C. 103(a) as being 
unpatentable over Dietz et al (US Patent 6,839,751), in view of Rosenberg et al. 
(US Patent Application Publication 2003/0023951) and Kawasaki (US Patent 
6,539,375), hereinafter referred to as Dietz, Rosenberg, and Kawasaki. 

In reference to claim 23, Dietz discloses a method for re-using information from data 
transactions for maintaining statistics in network monitoring. Dietz discloses (abstract; 
column 4, lines 14-33): 

• A method for analyzing a stream of usage data (Figure 3; column 8, lines 45-56) 
over a rolling time interval, comprising: 

• Defining a statistical model (i.e. statistical measures/network usage metrics; 
column 3, lines 14-33; column 17, lines 35-53) from a set of record events over a 
rolling time interval (i.e. flow-entry; column 10, line 55-column 11, line 5); 

• Defining the rolling time interval to include a plurality of update time intervals (i.e. 
time interval; column 33, line 15-column 34, line 30); 

• Receiving a record event from the stream of network usage data over the rolling 
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time interval, (i.e. new packet of flow arrives at monitor; column 8, lines 45-62; 
Figure 3-item 302); 

• Storing the record event for each update interval in a history cache (i.e. cache 
memory containing flow database; column 17, lines 4-34); 

• Generating a statistical model (i.e. statistical measures/network usage metrics; 
column 3, lines 14-33; column 17, lines 35-53) over the rolling time interval using 
the statistical model and each record event stored in the history cache (i.e. flow- 
entry; column 10, line 55-column 11, line 5); 

• Updating the statistical model using the statistical model and a most recent event 
for a most recent update time interval (updating statistical measures stored in the 
flow-entry; column 11, lines 50-58; column 12, lines 55-67). 

However, the reference fails to disclose updating only a portion of the statistical model 
associated with the most recent record. Nonetheless, this would have been an obvious 
modification to the aforementioned method to one of ordinary skill in the art at the time 
of the invention, as further evidenced by Rosenberg. 

In an analogous art, Rosenberg discloses a method for data analysis and 
statistical modeling (abstract). Rosenberg further discloses updating only a portion of 
the statistical model associated with the most recent record (i.e. updating statistical 
model for the new input data; paragraphs [0071]-[0073]; paragraph [0067]). This 
modification to the aforementioned method would have been obvious, because one of 
ordinary skill in the art would have been so motivated to present statistical summaries in 
a coherent and efficient manner for subset analysis to tackle large-scale problems 
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(Rosenberg; paragraph [0067], lines 22-24; paragraph [0073], lines 8-12). Although 
Dietz and Rosenberg teach substantial features of the invention, the reference fails to 
disclose: wherein each record event is associated with a user identifier. Nonetheless, 
this would have been an obvious modification to the aforementioned method to one of 
ordinary skill in the art at the time of the invention, as further evidenced by Kawasaki. 

In an analogous art, Kawasaki discloses associating record events to a use 
identification (i.e. user profile), used in a method for tracking network (i.e. Internet) 
usage of users, (column 2, lines 47-54; column 4, lines 42-61). This modification to the 
aforementioned method would have been obvious, because one of ordinary skill in the 
art would have been so motivated to identify network usage of specific users session 
tracking in client/server exchanges, (column 26, lines 17-37). 

In reference to claim 37, Dietz discloses a system for re-using information from data 
transactions for maintaining statistics in network monitoring. Dietz discloses (abstract; 
column 4, lines 14-33): 

• A network usage analysis system for analyzing a stream of network usage data 
(Figure 3; column 8, lines 45-56), comprising: 

• A data analysis system server (i.e. analyzer; column 6, lines 5-20; Figure 1-item 
108) which generates a statistical model (i.e. statistical measures/network usage 
metrics; column 3, lines 14-33; column 17, lines 35-53) from a set of record 
events (i.e. flow-entry; column 10, line 55-column 11, line 5); 

• Receiving a most recent record event, (i.e. new packet of flow arrives at monitor; 



Application/Control Number: 09/919,527 Page 11 

Art Unit: 2153 

column 8, lines 45-62; Figure 3-item 302) and 

( 

• Updating the statistical model using the most recent event by adding the most 
recent record to the statistical model (updating statistical measures stored in the 
flow-entry; column 11, lines 50-58; column 12, lines 55-67), wherein an identifier 
is associated with each record event (i.e. unique flow signature; column 11, lines 
15-49). 

However, the reference fails to disclose updating only a portion of the statistical model 
associated with the identifier. Nonetheless, this would have been an obvious 
modification to the aforementioned system to one of ordinary skill in the art at the time 
of the invention, as further evidenced by Rosenberg. 

In an analogous art, Rosenberg discloses a system for data analysis and 
statistical modeling (abstract). Rosenberg further discloses updating only a portion of 
the statistical model associated with the identifier (i.e. updating statistical model for the 
new input data; paragraphs [0071]-[0073]; paragraph [0067]). This modification to the 
aforementioned method would have been obvious, because one of ordinary skill in the 
art would have been so motivated to present statistical summaries in a coherent and 
efficient manner for subset analysis to tackle large-scale problems (Rosenberg; 
paragraph [0067], lines 22-24; paragraph [0073], lines 8-12). Although Dietz and 
Rosenberg teach substantial features of the invention, the reference fails to disclose: 
wherein each record event is associated with a customer usage. Nonetheless, this 
would have been an obvious modification to the aforementioned system to one of 
ordinary skill in the art at the time of the invention, as further evidenced by Kawasaki. 



Application/Control Number: 09/919,527 Page 12 

Art Unit: 2153 

In an analogous art, Kawasaki discloses associating record events to a customer 
usage (i.e. user profile), used in a method for tracking network (i.e. Internet) usage of 
users, (column 2, lines 47-54; column 4, lines 42-61). This modification to the 
aforementioned system would have been obvious, because one of ordinary skill in the 
art would have been so motivated to identify network usage of specific users session 
tracking in client/server exchanges, (column 26, lines 17-37). 

In reference to claim 45, Dietz discloses a system comprising hardware and software for 
re-using information from data transactions for maintaining statistics in network 
monitoring. Dietz discloses (abstract; column 4, lines 14-33): 
• A computer-readable medium having computer executable instructions (i.e. 
software; column 8, line 45-50) for performing a method for analyzing a of usage 
data, the method (Figure 3; column 8, lines 50-56), comprising: 

• Generating a statistical model (i.e. statistical measures/network usage metrics; 
column 3, lines 14-33; column 17, lines 35-53) from a set of record events (i.e. 
flow-entry; column 10, line 55-column 11, line 5); 

• Receiving a most recent record event, (i.e. new packet of flow arrives at monitor; 
column 8, lines 45-62; Figure 3-item 302) and 

• Updating the statistical model using the most recent event by adding the most 
recent record to the statistical model (updating statistical measures stored in the 
flow-entry; column 11, lines 50-58; column 12, lines 55-67), wherein an identifier 
is associated with each record event (i.e. unique flow signature; column 11, lines 
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15-49) 

However, the reference fails to disclose updating only a portion of the statistical model 
associated with the identifier. Nonetheless, this would have been an obvious 
modification to the aforementioned method to one of ordinary skill in the art at the time 
of the invention, as further evidenced by Rosenberg. 

In an analogous art, Rosenberg discloses a method for data analysis and 
statistical modeling (abstract). Rosenberg further discloses updating only a portion of 
the statistical model associated with the identifier (i.e. updating statistical model for the 
new input data; paragraphs [0071]-[0073]; paragraph [0067]). This modification to the 
aforementioned method would have been obvious, because one of ordinary skill in the 
art would have been so motivated to present statistical summaries in a coherent and 
efficient manner for subset analysis to tackle large-scale problems (Rosenberg; 
paragraph [0067], lines 22-24; paragraph [0073], lines 8-12). Although Dietz and 
Rosenberg teach substantial features of the invention, the reference fails to disclose: 
wherein each record event is associated with a customer usage. Nonetheless, this 
would have been an obvious modification to the aforementioned method to one of 
ordinary skill in the art at the time of the invention, as further evidenced by Kawasaki. 

In an analogous art, Kawasaki discloses associating record events to a customer 
usage (i.e. user profile), used in a method for tracking network (i.e. Internet) usage of 
users, (column 2, lines 47-54; column 4, lines 42-61). This modification to the 
aforementioned method would have been obvious, because one of ordinary skill in the 
art would have been so motivated to identify network usage of specific users session 
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tracking in client/server exchanges, (column 26, lines 17-37). 

In reference to claim 48, Dietz discloses a method for re-using information from data 
transactions for maintaining statistics in network monitoring. Dietz discloses (abstract; 
column 4, lines 14-33): 

• A network method for analyzing a stream of network usage data (Figure 3; column 8, 
lines 45-56), comprising: 

• Tracking and accumulating a set of usage data record events (i.e. analyzer; 
column 6, lines 5-20; Figure 1-item 108); 

• Generating a statistical model from the set of usage data record events (i.e. 
statistical measures/network usage metrics; column 3, lines 14-33; column 17, 
lines 35-53) from a set of record events (i.e. flow-entry; column 10, line 55- 
column 11, line 5); 

• Receiving a most recent record event, (i.e. new packet of flow arrives at monitor; 
column 8, lines 45-62; Figure 3-item 302) and 

• Independently updating the statistical model using the most recent event by 
adding the most recent record to the statistical model (updating statistical 
measures stored in the flow-entry; column 11, lines 50-58; column 12, lines 55- 
67), wherein an identifier is associated with each record event (i.e. unique flow 
signature; column 11, lines 15-49). 

However, the reference fails to disclose updating only a portion of the statistical model 
associated with the customer usage. Nonetheless, this would have been an obvious 
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modification to the aforementioned method to one of ordinary skill in the art at the time 
of the invention, as further evidenced by Rosenberg. 

In an analogous art, Rosenberg discloses a method for data analysis and 
statistical modeling (abstract). Rosenberg further discloses updating only a portion of 
the statistical model associated with the identifier (i.e. updating statistical model for the 
new input data; paragraphs [0071]-[0073]; paragraph [0067]). This modification to the 
aforementioned method would have been obvious, because one of ordinary skill in the 
art would have been so motivated to present statistical summaries in a coherent and 
efficient manner for subset analysis to tackle large-scale problems (Rosenberg; 
paragraph [0067], lines 22-24; paragraph [0073], lines 8-12). Although Dietz and 
Rosenberg teach substantial features of the invention, the reference fails to disclose: 
wherein each record event is associated with a customer usage. Nonetheless, this 
would have been an obvious modification to the aforementioned method to one of 
ordinary skill in the art at the time of the invention, as further evidenced by Kawasaki. 

In an analogous art, Kawasaki discloses associating record events to a customer 
usage (i.e. user profile), used in a method for tracking network (i.e. Internet) usage of 
users, and receiving a record event associated with a user (column 2, lines 47-54; 
column 4, lines 42-61). This modification to the aforementioned method would have 
been obvious, because one of ordinary skill in the art would have been so motivated to 
identify network usage of specific users session tracking in client/server exchanges, 
(column 26, lines 17-37). 
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In reference to claim 25, Dietz further discloses wherein generating a statistical model 
from the set of record events includes generating an aggregation table (i.e. flow-entry 
table) for tracking an aggregation of record events associated with an identifier 
(columns 11-12). 

In reference to claim 26, Dietz discloses the most recent record is associated with an 
identifier (i.e. unique flow signature); and wherein updating the statistical model includes 
updating only the aggregation of the record events in the tracking table for that identifier 
i.e. updating statistical measures of the flow-entry that matches the unique flow 
signature/previously encountered flow; column 17, lines 9-60; Figure 3-item 322). 

Claims 29, 31-36 is rejected under 35 U.S.C. 103(a) as being unpatentable over 
Dietz et al (US Patent 6,839,751), in view of Rosenberg et al. (US Patent 
Application Publication 2003/0023951) and Aboulnaga et al. (US Patent 6,460,045), 
hereinafter referred to as Dietz, Rosenberg and Aboulnaga. 

In reference to claim 29, Dietz discloses a method for re-using information from data 
transactions for maintaining statistics in network monitoring. Dietz discloses (abstract; 
column 4, lines 14-33): 

• A method for analyzing a stream of usage data (Figure 3; column 8, lines 45-56) 
over a rolling time interval, comprising: 

• Defining a statistical model (i.e. statistical measures/network usage metrics; 
column 3, lines 14-33; column 17, lines 35-53) from a set of record events (i.e. 



* 
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flow-entry; column 10, line 55-column 11, line 5); 

• Defining the rolling time interval to include a plurality of update time intervals (i.e. 
time interval; column 33, line 15-column 34, line 30); 

• Receiving a record event from the stream of network usage data over the rolling 
time interval, (i.e. new packet of flow arrives at monitor; column 8, lines 45-62; 
Figure 3-item 302); 

• Storing the record event for each update interval in a history cache (i.e. cache 
memory containing flow database; column 17, lines 4-34); 

• Generating a statistical model (i.e. statistical measures/network usage metrics; 
column 3, lines 14-33; column 17, lines 35-53) over the rolling time interval using 
the statistical model and each record event stored in the history cache (i.e. flow- 
entry; column 10, tine 55-column 11, line 5); 

• Updating the statistical model using the statistical model and a most recent event 
for a most recent update time interval (updating statistical measures stored in the 
flow-entry; column 11, lines 50-58; column 12, lines 55-67), 

However, the reference fails to disclose updating only a portion of the statistical model 
associated with the most recent record. Nonetheless, this would have been an obvious 
modification to the aforementioned method to one of ordinary skill in the art at the time 
of the invention, as further evidenced by Rosenberg. 

In an analogous art, Rosenberg discloses a method for data analysis and 
statistical modeling (abstract). Rosenberg further discloses updating only a portion of 
the statistical model associated with the most recent record (i.e. updating statistical 
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model for the new input data; paragraphs [0071]-[0073]; paragraph [0067]). This 
modification to the aforementioned method would have been obvious, because one of 
ordinary skill in the art would have been so motivated to present statistical summaries in 
a coherent and efficient manner for subset analysis to tackle large-scale problems 
(Rosenberg; paragraph [0067], lines 22-24; paragraph [0073], lines 8-12). 
Although Dietz and Rosenberg teach substantial features of the invention, the reference 
fails to disclose: the method generating a histogram statistical model representative of 
the network data, wherein the histogram having a first axis illustrating total usage 
defined by a number of bins, each bin having a usage variable range, and a second axis 
defined by a frequency corresponding to a number of users having a total usage within 
the usage variable range of each bin. Nonetheless, histogram statistical models were 
well known in the art at the time of the invention, as further evidenced by Aboulnaga. 
Therefore, this limitation would have been an obvious modification to the 
aforementioned method, as disclosed by the references, for one of ordinary skill in the 
art. 

In an analogous art, Aboulnaga discloses a method of building histogram 
statistical models, (column 5, line 37 to column 6, line 3). Aboulnaga further shows 
building a histogram that includes a first axis defined a number of bins (i.e. bins; Figure 
6-BUCKETS), each bin having a variable range (i.e. high to low; Figure 3; column 6, 
lines 30-55) and a second axis defined by a frequency (Figure 3&6) within the variable 
range of each bin, (columns 5-10). This modification would have been obvious to one of 
ordinary skill in the art, so as employ the bins and buckets of the flow-entry table (Dietz; 
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column 17, lines 9-35) to increase the accuracy of the statistical model estimations and 
thereby increasing process effectiveness, (Aboulnaga column 1, lines 54-55). 

In reference to claim 31, Dietz further discloses wherein defining the statistical model 
includes an aggregation table (i.e. flow-entry table) of each record event stored in the 
history cache (i.e. flow-entry table), (columns 11-12). 

In reference to claim 32, Dietz discloses wherein the history cache is an array of 
memory segments, wherein the number of memory segments is equal to the number of 
update time intervals in the rolling time interval, (columns 17-18). 

In reference to claim 33, Dietz discloses defining the statistical model to include an 
aggregation of each record event stored in the history cache (i.e. flow-entry table; 
columns 17-18). 

In reference to claim 34, Dietz discloses defining an index array associated including a 
set of contiguous index segments, wherein each index segment including a pointer to 
the memory segment storing in the history cache storing the next consecutive record 
event, (i.e. lookup engine; columns 17-18). 

In reference to claim 35, Dietz discloses defining a first pointer to the index segment 
associated with the memory segment storing the least recent record' event, (i.e. lookup 
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engine; columns 17-18). 
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In reference to claim 36, Aboulnaga discloses generating a histogram statistical model 
from the aggregation table (column 5, line 37 to column 6, line 3); and Dietz discloses 
updating only the portion of the histogram statistical model associated with most recent 
record event, (column 17, lines 9-60). 

Claims 2-6 are rejected under 35 U.S.C. 103(a) as being unpatentable over Dietz 
and Rosenberg as applied to claim 1 above, and further in view of Steinbiss et al. 
(US Patent 6,823,307), hereinafter referred to as Steinbiss. 

In reference to claim 2, although Dietz and Rosenberg disclose substantial 
features of the aforementioned method, the references fail to explicitly disclose the 
method further comprising the step of: updating the statistical model includes removing 
a least recent event from the statistical model. Nonetheless, this would have been an 
obvious modification to the aforementioned method, to one of ordinary skill in the art at 
the time of the invention, as further evidenced by Steinbiss. 

In an analogous art, Steinbiss discloses a method for employing stochastic 
models that involves storing recently recognized elements in a cache, (abstract; column 
2, lines 25-38; and column 5, lines 15-30). Steinbiss further discloses removing the least 
recently stored element, (column 5, line 60 to column 6, line 7). This modification would 
have been obvious, because one of ordinary skill in the art would have been so 
motivated to implement this feature so as to maximize available memory space, thereby 
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reducing cost associated with larger capacity cache memories, (Steinbiss column 5, line 
66 to column 6, line 3). 

In reference to claim 3, although Dietz and Rosenberg disclose substantial 
features of the aforementioned method such as storing the set of records in a history 
cache (column 17, lines 18-20), the references fail to explicitly disclose the method 
further comprising the step of: if the history cache is full, updating the statistical model 
includes removing a least recent event from the statistical model. Nonetheless, this 
would have been an obvious modification to the aforementioned method, to one of 
ordinary skill in the art at the time of the invention, as further evidenced by Steinbiss. 

In an analogous art, Steinbiss discloses a method for employing stochastic 
models that involves storing recently recognized elements in a cache, (abstract; column 
2, lines 25-38; and column 5, lines 15-30). Steinbiss further discloses once the cache is 
full, removing the least recently stored element, (column 5, line 60 to column 6, line 7). 
This modification would have been obvious, because one of ordinary skill in the art 
would have been so motivated to implement this feature so as to maximize available 
memory space, thereby reducing cost associated with larger capacity cache memories, 
(Steinbiss column 5, line 66 to column 6, line 3). 

In reference to claim 4, Dietz discloses defining the statistical model to include an 
aggregation of each record event stored in the history cache (columns 11-12). 
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In reference to claim 5, Dietz further discloses wherein generating a statistical 
model from the set of record events includes generating an aggregation table (i.e. flow- 
entry table) for tracking an aggregation of record events associated with an identifier 
(columns 1 1-12). 

In reference to claims 6, 9 Dietz discloses generating a complex statistical model 
representative of the network data from the aggregation table (column 17, lines 35-59). 

Claim 7 is rejected under 35 U.S.C. 103(a) as being unpatentable over Dietz, 
Rosenberg and Steinbiss as applied to claim 3 above, and further in view of 
Aboulnaga et al. (US Patent 6,460,045), hereinafter referred to as Dietz, Rosenberg 
and Aboulnaga. 

In reference to claim 7, although Dietz, Rosenberg and Steinbiss discloses substantial 
features of the claimed invention, the references fail to show generating a histogram 
statistical model representative of the network data from the aggregation table. 
Nonetheless, histogram statistical models were well known in the art at the time of the 
invention, as further evidenced by Aboulnaga. Therefore, this limitation would have 
been an obvious modification to the aforementioned method, as disclosed by the 
references, for one of ordinary skill in the art. 

In an analogous art, Aboulnaga discloses a method of building histogram 
statistical models, (column 5, line 37 to column 6, line 3). Aboulnaga further shows 
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building a histogram that includes a first axis defined a number of bins (i.e. bins; Figure 
6-BUCKETS), each bin having a variable range (i.e. high to low; Figure 3; column 6, 
lines 30-55) and a second axis defined by a frequency (Figure 3&6) within the variable 
range of each bin, (columns 5-10). This modification would have been obvious to one of 
ordinary skill in the art, so as employ the bins and buckets of the aggregation table (I.e. 
flow-entry table; Dietz; column 17, lines 9-35) to increase the accuracy of the statistical 
model estimations and thereby increasing process effectiveness, (Aboulnaga column 1, 
lines 54-55). 

Claims 24 and 38-42 are rejected under 35 U.S.C. 103(a) as being unpatentable 
over Dietz, Rosenberg and Kawasaki as applied to claims 23 and 37 above, and 
further in view of Steinbiss et al. (US Patent 6,823,307), hereinafter referred to as 
Steinbiss. 

In reference to claim 24, although Dietz, Rosenberg and Kawasaki disclose 
substantial features of the aforementioned method such as storing the set of records in 
a history cache (column 17, lines 18-20), the references fail to explicitly disclose the 
method further comprising the step of: if the history cache is full, updating the statistical 
model includes removing a least recent event from the statistical model. Nonetheless, 
this would have been an obvious modification to the aforementioned method, to one of 
ordinary skill in the art at the time of the invention, as further evidenced by Steinbiss. 

In an analogous art, Steinbiss discloses a method for employing stochastic 
models that involves storing recently recognized elements in a cache, (abstract; column 
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2, lines 25-38; and column 5, lines 15-30). Steinbiss further discloses once the cache is 
full, removing the least recently stored element, (column 5, line 60 to column 6, line 7). 
This modification would have been obvious, because one of ordinary skill in the art 
would have been so motivated to implement this feature so as to maximize available 
memory space, thereby reducing cost associated with larger capacity cache memories, 
(Steinbiss column 5, line 66 to column 6, line 3). 

In reference to claims 2 and 38, although Dietz discloses substantial features of the 
aforementioned method, the reference fails to explicitly disclose the method further 
comprising the step of: updating the statistical model includes removing a least recent 
event from the statistical model. Nonetheless, this would have been an obvious 
modification to the aforementioned method, to one of ordinary skill in the art at the time 
of the invention, as further evidenced by Steinbiss. 

In an analogous art, Steinbiss discloses a method for employing stochastic 
models that involves storing recently recognized elements in a cache, (abstract; column 
2, lines 25-38; and column 5, lines 15-30). Steinbiss further discloses removing the least 
recently stored element, (column 5, line 60 to column 6, line 7). This modification would 
have been obvious, because one of ordinary skill in the art would have been so 
motivated to implement this feature so as to maximize available memory space, thereby 
reducing cost associated with larger capacity cache memories, (Steinbiss column 5, line 
66 to column 6, line 3). 

* 

In reference to claim 39, although Dietz discloses substantial features of the 
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aforementioned method such as storing the set of records in a history cache (column 
17, lines 18-20), the reference fails to explicitly disclose the method further comprising 
the step of: if the history cache is full, updating the statistical model includes removing a 
least recent event from the statistical model. Nonetheless, this would have been an 
obvious modification to the aforementioned method, to one of ordinary skill in the art at 
the time of the invention, as further evidenced by Steinbiss. 

In an analogous art, Steinbiss discloses a method for employing stochastic 
models that involves storing recently recognized elements in a cache, (abstract; column 
2, lines 25-38; and column 5, lines 15-30). Steinbiss further discloses once the cache is 
full, removing the least recently stored element, (column 5, line 60 to column 6, line 7). 
This modification would have been obvious, because one of ordinary skill in the art 
would have been so motivated to implement this feature so as to maximize available 
memory space, thereby reducing cost associated with larger capacity cache memories, 
(Steinbiss column 5, line 66 to column 6, line 3). 

In reference to claim 40, Dietz discloses defining the statistical model to include 
an aggregation of each record event stored in the history cache (columns 11-12). 

In reference to claim 41 , Dietz further discloses wherein generating a statistical 
model from the set of record events includes generating an aggregation table (i.e. flow- 
entry table) for tracking an aggregation of record events associated with an identifier 
(columns 11-12). 
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In reference to claim 42, Dietz discloses generating a complex statistical model 
representative of the network data from the aggregation table (column 17, lines 35-59). 

Claim 27 is rejected under 35 U.S.C. 103(a) as being unpatentable over Dietz, 
Rosenberg and Kawasaki as applied to claim 23 above, and further in view of 
Aboulnaga et al. (US Patent 6,460,045), hereinafter referred to as Aboulnaga. 

In reference to claim 27, although Dietz, Rosenberg and Kawasaki disclose substantial 

features of the claimed invention, the references fail to show generating a histogram 

* 

statistical model representative of the network data from the aggregation table. 
Nonetheless, histogram statistical models were well known in the art at the time of the 
invention, as further evidenced by Aboulnaga. Therefore, this limitation would have 
been an obvious modification to the aforementioned method, as disclosed by the 
references, for one of ordinary skill in the art. 

In an analogous art, Aboulnaga discloses a method of building histogram 
statistical models, (column 5, line 37 to column 6, line 3). Aboulnaga further shows 
building a histogram that includes a first axis defined a number of bins (i.e. bins; Figure 
6-BUCKETS), each bin having a variable range (i.e. high to low; Figure 3; column 6, 
lines 30-55) and a second axis defined by a frequency (Figure 3&6) within the variable 
range of each bin, (columns 5-10). This modification would have been obvious to one of 
ordinary skill in the art, so as employ the bins and buckets of the aggregation table (I.e. 
flow-entry table; Dietz; column 17, lines 9-35) to increase the accuracy of the statistical 
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model estimations and thereby increasing process effectiveness, (Aboulnaga column 1, 
lines 54-55). 

Claim 30 is rejected under 35 U.S.C. 103(a) as being unpatentable over Dietz and 
Rosenberg and Aboulnaga as applied to claim 29 above, and further in view of 
Steinbiss et al. (US Patent 6,823,307), hereinafter referred to as Steinbiss. 

In reference to claim 30, although Dietz, Rosenberg and Aboulnaga disclose 
substantial features of the aforementioned method such as storing the set of records in 
a history cache (column 17, lines 18-20), the references fail to explicitly disclose the 
method further comprising the step of: if the history cache is full, updating the statistical 
model includes removing a least recent event from the statistical model. Nonetheless, 
this would have been an obvious modification to the aforementioned method, to one of 
ordinary skill in the art at the time of the invention, as further evidenced by Steinbiss. 

In an analogous art, Steinbiss discloses a method for employing stochastic 
models that involves storing recently recognized elements in a cache, (abstract; column 
2, lines 25-38; and column 5, lines 15-30). Steinbiss further discloses once the cache is 
full, removing the least recently stored element, (column 5, line 60 to column 6, line 7). 
This modification would have been obvious, because one of ordinary skill in the art 
would have been so motivated to implement this feature so as to maximize available 
memory space, thereby reducing cost associated with larger capacity cache memories, 
(Steinbiss column 5, line 66 to column 6, line 3). 



Application/Control Number: 09/919,527 Page 28 

Art Unit: 2153 



Allowable Subject Matter 

Claims 8-11, 14-22, 28, and 43-44 are objected to as being dependent upon a 
rejected base claim, but would be allowable if rewritten in independent form including all 
of the limitations of the base claim and any intervening claims. 

Claims 46-47 is allowable as the prior art of record fails to teach or suggest 
individually or in combination the claimed limitations of a method for analyzing a stream 
of network usage data comprising updating a statistical model, wherein updating the 
statistical model includes updating only the aggregation of records in the tracking table 

i 

for that identifier . 

Conclusion 

THIS ACTION IS MADE FINAL, Applicant is reminded of the extension of time 
policy as set forth in 37 CFR 1.136(a). 

A shortened statutory period for reply to this final action is set to expire THREE 
MONTHS from the mailing date of this action. In the event a first reply is filed within 
TWO MONTHS of the mailing date of this final action and the advisory action is not 
mailed until after the end of the THREE-MONTH shortened statutory period, then the 
shortened statutory period will expire on the date the advisory action is mailed, and any 
extension fee pursuant to 37 CFR 1.136(a) will be calculated from the mailing date of 
the advisory action. In no event, however, will the statutory period for reply expire later 
than SIX MONTHS from the mailing date of this final action. Any inquiry concerning this 
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communication or earlier communications from the examiner should be directed to 
LaShanya R Nash whose telephone number is (571) 272-3957. The examiner can 
normally be reached on 9am-5pm. 

If attempts to reach the examiner by telephone are unsuccessful, the examiner's 
supervisor, Glenton Burgess can be reached on (571) 272-3949. The fax phone 
number for the organization where this application or proceeding is assigned is (571) 
273-8300. 

Information regarding the status of an application may be obtained from the 
Patent Application Information Retrieval (PAIR) system. Status information for 
published applications may be obtained from either Private PAIR or Public PAIR. 
Status information for unpublished applications is available through Private PAIR only. 
For more information about the PAIR system, see http://pair-direct.uspto.gov. Should 
you have questions on access to the Private PAIR system, contact the Electronic 
Business Center (EBC) at 866-217-9197 (toll-free). 
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